VYPR

OrdaSoft Touch Slider

by Joomla

CVEs (1)

  • CVE-2026-102781MedOct 7, 2026
    risk 0.45cvss —epss —

    Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call…